StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3
33
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
libwebp@1.2.3-r0
1.2.3-r2
10
library/nginx:1.21:1.21.62bcabc23b454
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
6
library/nginx:1.19df13abe416e3
libwebp@0.6.1-2
0.6.1-2+deb10u3
5
ghcr.io/stacksimplify/kubenginx:0.1.0:1.0.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3
5
assistiot/dlt_api:2.0.0e36a8922fa0c
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
3
ciscolabs/rtsp-client:latesta7b60ec88285
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
3
ciscolabs/rtsp-server:latestb59fc10bb821
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
3
conduction/openwebconcept:4.8ee2121b569ac
libwebp@0.6.1-2
0.6.1-2+deb10u3
3
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
10.0.1
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
libwebp@1.2.4-r1
1.2.4-r3
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
3
ghcr.io/stacksimplify/kubenginx:0.4.0:4.0.0279eb855e6c7
libwebp@0.6.1-2
0.6.1-2+deb10u3
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
libwebp@1.2.4-r2
1.2.4-r3
2
amancevice/superset:0.35.212a0a9e66550
libwebp@0.6.1-2
0.6.1-2+deb10u3
2
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
2
daniacobext/airports-frontend:latest9eae4d39fc33
libwebp@1.2.4-r2
1.2.4-r3
2
dependencytrack/frontend:4.6.124422d762e08
libwebp@1.2.3-r0
1.2.3-r2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
2
ldapaccountmanager/lam:8.0.1d46cf25d1dda
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
2
library/nginx:1.176fff55753e3b
libwebp@0.6.1-2
0.6.1-2+deb10u3
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
libwebp@0.6.1-2
0.6.1-2+deb10u3
2
martinaif/backstage-k8s-demo-frontend:test1f07fbe15e5b5
libwebp@0.6.1-2
0.6.1-2+deb10u3
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
2
openmf/community-app:latest496b60a51f28
libwebp@0.6.1-2
0.6.1-2+deb10u3
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
2
pecan/bety:5.4.1f825d480cd62
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
2
phpipam/phpipam-cron:v1.5.2f770577cb946
libwebp@1.2.2-r0
1.2.2-r2
2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
libwebp@1.2.2-r0
1.2.2-r2
2
postgis/postgis:15-3.3a2fc46b52819
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
2
privatebin/pdo:1.3.500466418121c
libwebp@1.2.2-r0
1.2.2-r2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
2
taigaio/taiga-front:latest570c8792ce80
libwebp@1.2.4-r1
1.2.4-r3
2
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
libwebp@0.6.1-2
10.0.1
0.6.1-2+deb10u3
2
yzhou442/equiz:latesta3f7ca69e28d
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
2
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
libwebp@1.2.2-r0
1.2.2-r2
2
afrank/mozalert-controller:latestd463c37b08d7
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
libwebp@1.2.3-r0
1.2.3-r2
1
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
akaunting/akaunting:3.0.1552811b36ec3a
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pillow@9.4.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pillow@9.4.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
anonaddy/anonaddy:0.12.3957a95565166
libwebp@1.2.3-r0
1.2.3-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.